QCS Security Advisory Desk
Network vulnerabilities and vendor patches, verified at the source.
Monitor network-edge vulnerabilities, known exploitation, affected products, mitigations, and vendor patch guidance without waiting for a weekly editorial cycle.
- 01Official sourceMonitor vendors and trusted authorities.
- 02Verify contextCheck products, exposure, and evidence.
- 03Set prioritySeparate urgent action from useful reading.
- 04Act or learnPatch, mitigate, investigate, or prepare.
Live intelligence
See the items that can change today's patch or mitigation plan.
Priority combines source severity, known exploitation, remote attack conditions, recency, and network-edge relevance.
Cisco / Priority 100
Cisco IOS XR Software Security Hardening Release: September 2026
Cisco discovered multiple security vulnerabilities in its IOS XR software during internal testing. These issues could allow attackers to cause serious problems if exploited. Cisco has released software updates to fix these vulnerabilities and strongly recommends users apply these updates promptly. There are no alternative workarounds to protect against these issues.
- Published
- 3 Sept 2026
- CVSS
- Not scored
- Verified
- 3 Sept 2026
Cisco / Priority 100
Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
A security weakness in certain Cisco Nexus 9000 Series Switches lets an attacker connect remotely without needing to log in and run harmful commands with full admin rights. This happens because specific network ports (43210 and 43211) are open by default, letting attackers send malicious data. Exploiting this could also crash a key process, forcing the device to restart. Cisco has published software updates and workarounds to protect devices.
- Published
- 2 Sept 2026
- CVSS
- Not scored
- Verified
- 3 Sept 2026
Cisco / Priority 100
Cisco Crosswork Security Hardening Release: August 2026
Cisco has identified multiple security weaknesses in its Crosswork product line after an internal review. These issues could allow attackers to control software functionality, access protected credentials, execute harmful database commands, or manipulate files improperly. Cisco released software updates to fix these problems, and no workaround solutions are available. Users are advised to upgrade their software promptly to protect their systems.
- Published
- 21 Aug 2026
- CVSS
- Not scored
- Verified
- 31 Aug 2026
Cisco / Priority 100
Cisco Secure Workload Software Security Hardening Release: August 2026
Cisco conducted an internal security review of its Secure Workload software and found several security weaknesses that could allow attackers to take control, bypass protections, or cause harmful crashes. These issues were discovered during internal testing and are not known to be exploited in the wild. Cisco has released software updates to fix these problems, but there are no temporary fixes available. Customers should update their software as soon as possible to protect their systems.
- Published
- 19 Aug 2026
- CVSS
- Not scored
- Verified
- 19 Aug 2026
Cisco / Priority 100
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
A security flaw in Cisco Secure Firewall Management Center (FMC) software lets attackers remotely bypass login controls and run harmful scripts. This could let them take full control over the system behind the firewall. The issue exists because a system process starts incorrectly when the device boots. Attackers can exploit it by sending specially crafted web requests to the device. If your firewall management interface isn’t accessible from the internet, the risk is lower. Cisco has released updates to fix this problem, but there are no other workarounds.
- Published
- 3 Aug 2026
- CVSS
- Not scored
- Verified
- 4 Aug 2026
Cisco / Priority 100
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability
Certain Cisco desk and video phones have a security flaw that can allow remote attackers to disable the phone by overloading its memory using specially crafted web packets. This causes the phone to stop working until it is manually restarted. To be vulnerable, the phone must be registered with Cisco Unified Communications Manager and have its Web Access feature turned on, which it is not by default. Cisco has released updates that fix this issue, but no temporary workaround fully addresses the problem.
- Published
- 2 Sept 2026
- CVSS
- Not scored
- Verified
- 3 Sept 2026
Cisco / Priority 100
Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
Cisco BroadWorks has a security flaw in the way it processes XML data, which could let an attacker who isn't logged in read sensitive system files. This happens because the system by default allows external references in XML files, which can be exploited by sending specially crafted messages. Cisco has released software updates to fix this issue. There is no workaround available to prevent this problem, so updating is necessary.
- Published
- 19 Aug 2026
- CVSS
- Not scored
- Verified
- 19 Aug 2026
Cisco / Priority 100
ClamAV Vulnerabilities Affecting Cisco Products: August 2026
Multiple security flaws have been found in ClamAV, an antivirus scanning component used by some Cisco software. These flaws could let an attacker send specially crafted files to disrupt the scanning process, causing it to stop working temporarily (a denial of service). Cisco has fixed these flaws in newer software versions for affected products. There are no workarounds to prevent these issues, so updating the software is the best way to stay protected.
- Published
- 13 Aug 2026
- CVSS
- Not scored
- Verified
- 13 Aug 2026
Cisco / Priority 100
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
A security flaw in Cisco Secure Firewall Management Center software lets attackers log in remotely without needing to authenticate, using a built-in low-privileged account. This access can expose sensitive system data. While the account limits access rights, the vulnerability still poses significant risk, especially combined with other flaws that might allow attackers to gain higher privileges. Cisco warns that this threat is serious and recommends updating the software to fix it, as no temporary workarounds exist. Limiting public internet exposure of the management interface can reduce risk.
- Published
- 11 Aug 2026
- CVSS
- Not scored
- Verified
- 11 Aug 2026
Cisco / Priority 100
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
A security flaw exists in Cisco Secure Firewall devices that use the Remote Access SSL VPN service. This flaw lets an attacker who is not logged in send a special message that causes the device to restart unexpectedly, leading to service interruptions. Cisco has released updates that fix this issue, but no temporary solutions are available.
- Published
- 11 Aug 2026
- CVSS
- Not scored
- Verified
- 11 Aug 2026
Cisco / Priority 100
Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability
A security flaw in Cisco IOS XE Software's Blocks Extensible Exchange Protocol (BEEP) feature lets attackers cause a device to crash and restart unexpectedly. Attackers do this by sending a specially crafted BEEP SOAP message. This leads to a denial of service (DoS), temporarily disrupting device operation. Cisco has released software updates to fix this issue, and currently, no other ways to avoid this problem exist.
- Published
- 5 Aug 2026
- CVSS
- Not scored
- Verified
- 6 Aug 2026
Cisco / Priority 100
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
A security flaw in Cisco IOS and IOS XE software's Extensible Messaging Client Protocol (XMCP) lets attackers remotely crash affected devices. This happens when attackers send malformed XMCP packets, causing the device to unexpectedly reload and become unavailable. The attacker does not need special access or usernames to cause this issue. Cisco has released software updates to fix the problem. There are no workarounds, but a mitigation involving access control lists can limit which clients can connect, reducing risk.
- Published
- 5 Aug 2026
- CVSS
- Not scored
- Verified
- 6 Aug 2026
